# Azion CLI waf

The Azion CLI `waf` commands create, list, describe, update, and delete [WAF rule sets](/en/documentation/platform/firewall/waf/rules-set/). A rule set holds one threshold for each threat it covers, a threat name paired with a sensitivity, and the CLI output calls it a WAF. The options every command accepts, such as `--format`, `--out`, and `-y`, are on [Global options](/en/documentation/devtools/cli/globals/).

---

## Create

`azion create waf` creates a rule set with the name and settings you pass:

```bash
azion create waf [flags]
```

| Flag                | Short | Type   | Default | Description                                                                                                           |
| ------------------- | ----- | ------ | ------- | --------------------------------------------------------------------------------------------------------------------- |
| `--active`          | —     | string | —       | Turns the rule set on (`true`) or off (`false`).                                                                      |
| `--engine-version`  | —     | string | —       | Version of the WAF engine. A rule set created without it gets `2021-Q3`.                                              |
| `--file`            | —     | string | —       | Path to a JSON file with the attributes of the rule set. Use `-` to read the JSON from standard input.                |
| `--name`            | —     | string | —       | Name of the rule set.                                                                                                 |
| `--product-version` | —     | string | —       | Product version of the rule set. A rule set created without it gets `1.0`.                                            |
| `--rulesets`        | —     | string | —       | Comma-separated list of the IDs of the rulesets to turn on. A rule set created without it gets `1`.                   |
| `--thresholds`      | —     | string | —       | Comma-separated list of `threat=sensitivity` pairs. A rule set created without it gets all eight threats at `medium`. |
| `--type`            | —     | string | —       | Type of the WAF engine. A rule set created without it gets `score`.                                                   |

The eight threats are `cross_site_scripting`, `directory_traversal`, `evading_tricks`, `file_upload`, `identified_attack`, `remote_file_inclusion`, `sql_injection`, and `unwanted_access`. The sensitivity takes `highest`, `high`, `medium`, `low`, or `lowest`.

This command creates an active rule set named `my-strict-waf` with `highest` sensitivity for cross-site scripting and `high` for SQL injection:

```bash
azion create waf --name my-strict-waf --active true --engine-version 2021-Q3 --type score --rulesets 1 --thresholds 'cross_site_scripting=highest,sql_injection=high'
```

The command prints the ID of the rule set:

```text
Created WAF with ID 12348
```

The rule set holds only the thresholds you pass: `azion describe waf --waf-id 12348 --format json` lists `cross_site_scripting` at `highest` and `sql_injection` at `high`, and no other threat.

A sensitivity outside these five values is refused:

```text
Error: Invalid sensitivity value for threshold. Valid values: highest, high, medium, low, lowest
```

---

## List

`azion list waf` lists the rule sets of your account, 50 to a page:

```bash
azion list waf [flags]
```

| Flag          | Short | Type   | Default | Description                                                                                                       |
| ------------- | ----- | ------ | ------- | ----------------------------------------------------------------------------------------------------------------- |
| `--details`   | —     | —      | —       | Adds the `PRODUCT VERSION`, `LAST EDITOR`, and `LAST MODIFIED` columns to the `ID`, `NAME`, and `ACTIVE` columns. |
| `--filter`    | —     | string | —       | Name to filter the list by.                                                                                       |
| `--order-by`  | —     | string | —       | Field to sort the list by.                                                                                        |
| `--page`      | —     | int    | `1`     | Number of the page to return.                                                                                     |
| `--page-size` | —     | int    | `50`    | Number of rule sets on each page.                                                                                 |

This command lists the rule sets of the account:

```bash
azion list waf
```

The command prints one row per rule set:

```text
ID     NAME           ACTIVE
12345  my-blog-waf    true
12346  my-store-waf   true
12347  my-waf         true
12348  my-strict-waf  true
12349  my-site-waf    true
```

---

## Describe

`azion describe waf` prints the settings of one rule set:

```bash
azion describe waf [flags]
```

| Flag       | Short | Type | Default | Description                     |
| ---------- | ----- | ---- | ------- | ------------------------------- |
| `--waf-id` | —     | int  | —       | ID of the rule set to describe. |

This command describes the rule set with ID `12347`, created with `--name` and `--active` only:

```bash
azion describe waf --waf-id 12347
```

The command prints the name, the state, and the engine settings of the rule set. All eight threats carry the default `medium` sensitivity:

```text
ID:                12347
Active:            true
Name:              my-waf
Last Editor:       you@example.com
Modified at:       "2026-01-01T12:00:00.058811Z"
Product Version:   "1.0"
Engine Settings:   {"attributes":{"rulesets":[1],"thresholds":[{"sensitivity":"medium","threat":"cross_site_scripting"},{"sensitivity":"medium","threat":"directory_traversal"},{"sensitivity":"medium","threat":"evading_tricks"},{"sensitivity":"medium","threat":"file_upload"},{"sensitivity":"medium","threat":"identified_attack"},{"sensitivity":"medium","threat":"remote_file_inclusion"},{"sensitivity":"medium","threat":"sql_injection"},{"sensitivity":"medium","threat":"unwanted_access"}]},"engine_version":"2021-Q3","type":"score"}
```

With `--format json`, the command prints the full object: `active`, `engine_settings`, `id`, `is_versioned`, `last_editor`, `last_modified`, `name`, `product_version`, `version`, `version_id`, and `version_state`. The `engine_settings` object holds `engine_version`, `type`, and an `attributes` object with the `rulesets` and `thresholds` that the create and update flags set.

An ID that does not exist fails with this error:

```text
Error: Failed to get the WAF: The given ID or API's endpoint doesn't exist or isn't available. Check that the identifying information is correct. Check your settings and try again. If the error persists, contact Azion support
```

---

## Update

`azion update waf` changes the name, the active state, or the engine settings of a rule set:

```bash
azion update waf [flags]
```

| Flag               | Short | Type   | Default | Description                                                                                             |
| ------------------ | ----- | ------ | ------- | ------------------------------------------------------------------------------------------------------- |
| `--active`         | —     | string | —       | Turns the rule set on (`true`) or off (`false`).                                                        |
| `--engine-version` | —     | string | —       | Version of the WAF engine.                                                                              |
| `--file`           | —     | string | —       | Path to a JSON file with the attributes to change. Use `-` to read the JSON from standard input.        |
| `--name`           | —     | string | —       | New name of the rule set.                                                                               |
| `--rulesets`       | —     | string | —       | Comma-separated list of the IDs of the rulesets to turn on.                                             |
| `--thresholds`     | —     | string | —       | Comma-separated list of `threat=sensitivity` pairs. Replaces the whole list of thresholds.              |
| `--type`           | —     | string | —       | Type of the WAF engine.                                                                                 |
| `--waf-id`         | —     | int    | —       | **Required**, with `--file` too. ID of the rule set to update. Without it, the command asks for the ID. |

> **Caution**
>
> `--thresholds` replaces the whole list. A threat you leave out of the value loses its threshold, so pass every threat the rule set must keep.

This command renames the rule set with ID `12347` to `my-waf-renamed` and sets SQL injection to `lowest` sensitivity:

```bash
azion update waf --waf-id 12347 --name my-waf-renamed --thresholds 'sql_injection=lowest'
```

The command prints the ID of the updated rule set:

```text
Updated WAF with ID 12347
```

After this update, `azion describe waf --waf-id 12347 --format json` returns one threshold, `sql_injection` at `lowest`. The other seven threats are gone from the rule set.

---

## Delete

`azion delete waf` deletes a rule set:

```bash
azion delete waf [flags]
```

| Flag       | Short | Type | Default | Description                   |
| ---------- | ----- | ---- | ------- | ----------------------------- |
| `--waf-id` | —     | int  | —       | ID of the rule set to delete. |

This command deletes the rule set with ID `12347`:

```bash
azion delete waf --waf-id 12347
```

The command confirms the deletion:

```text
WAF 12347 was successfully deleted
```

---

## Use a JSON file

`azion create waf` and `azion update waf` read the attributes of the rule set from a JSON file with `--file`.

This file creates an active rule set named `my-site-waf` with `high` sensitivity for SQL injection. The command reads `name`, `active`, and `engine_settings` from it:

```json
{
  "name": "my-site-waf",
  "active": true,
  "engine_settings": {
    "engine_version": "2021-Q3",
    "type": "score",
    "attributes": {
      "rulesets": [1],
      "thresholds": [
        {"threat": "sql_injection", "sensitivity": "high"}
      ]
    }
  }
}
```

Pass the file to the create command:

```bash
azion create waf --file waf-create.json
```

The command prints the ID of the rule set:

```text
Created WAF with ID 12349
```

The rule set created from this file holds one threshold, `sql_injection` at `high`, as `azion describe waf --format json` shows.

On update, the command does not read `"id"` from the file. Pass `--waf-id` on the command line, or the command asks for the ID. This file renames the rule set with ID `12349`:

```json
{
  "id": 12349,
  "name": "my-site-waf-updated"
}
```

Pass the file and the ID to the update command:

```bash
azion update waf --waf-id 12349 --file waf-update.json
```

The command prints the ID of the updated rule set:

```text
Updated WAF with ID 12349
```

The update is partial: the file leaves `active` out, and the rule set stays active.

---

## Related resources

- [Global options](/en/documentation/devtools/cli/globals.md): The options every command accepts, such as `--format`, `--out`, and `-y`.
- [Rule sets](/en/documentation/platform/firewall/waf/rules-set.md): What each threat detects, and the score at which each sensitivity blocks a request.
- [Azion CLI waf-exceptions](/en/documentation/devtools/cli/resources/waf-exceptions.md): The commands that add exceptions to a rule set by rule ID, path, or condition.
- [Azion CLI firewall](/en/documentation/devtools/cli/resources/firewall.md): The commands that turn WAF on or off for a firewall.
